Security
Comprehensive Objective Assessment (Qns &
Ans)
2025
Question 1 (Multiple Choice)
Question:
Which of the following best defines information security
governance in a modern enterprise security program?
A) A set of technical configurations aimed solely at protecting
network perimeters
B) The formal framework that aligns security strategies with
business objectives and regulatory requirements
C) The process of installing firewalls and intrusion detection
systems
D) A reactive incident response protocol initiated after a
cyberattack
©2025
, Correct ANS:
B) The formal framework that aligns security strategies with
business objectives and regulatory requirements
Rationale:
Information security governance ensures that an organization’s
security strategies and practices are in lockstep with its business
goals, risk tolerance, and legal obligations. It encompasses the
policies, procedures, and controls that guide the overall security
posture—not merely technical configurations or reactive
responses.
---
Question 2 (Fill in the Blank)
Question:
The principle of ensuring that no unauthorized actions occur and
that every action is attributable to a defined entity is known as
________ .
Correct ANS:
Accountability
©2025
, Rationale:
Accountability in information systems security means that every
action within the system can be traced to an individual or process.
This traceability is essential for both deterring malicious behavior
and conducting effective forensic investigations.
---
Question 3 (True/False)
Question:
A secure information system architecture relies on a single, highly
fortified defense mechanism to protect against cyber threats.
Correct ANS:
False
Rationale:
Modern security architectures adopt a defense in depth strategy,
layering multiple security controls across technological,
administrative, and physical domains. Relying on a single
mechanism would create a weak point and is contrary to best
practices in systems security.
©2025
, ---
Question 4 (Multiple Response)
Question:
Select all the components that are integral to a comprehensive risk
assessment within an information systems security program:
A) Threat identification
B) Asset valuation
C) Risk mitigation strategies
D) Vulnerability assessments
E) Profit margin analysis
Correct ANS:
A, B, C, D
Rationale:
A thorough risk assessment involves identifying potential threats,
valuing the assets at risk, evaluating vulnerabilities, and
determining suitable mitigation strategies. Profit margin analysis,
however, pertains to financial performance and is not a direct
element of security risk assessment.
©2025